Shared responsibility model
The division of security duties between a cloud provider and its customer, which shifts depending on the service type.
Providers secure the infrastructure. Customers secure their identities, access, configuration, and data. The line moves between IaaS, PaaS, and SaaS, but data and identity remain the customer's responsibility in every model.
Most cloud breaches trace to the customer side of the line, typically a misconfiguration or a compromised account rather than any failure by the provider.
Where this comes up
Shared responsibility model sits inside our microsoft 365 and cloud work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.